Wednesday, September 2, 2026, 00:01
Home»Cryptocurrency»Fake Claude Desktop App Used to Deploy RevStealer Malware...
RSS

Fake Claude Desktop App Used to Deploy RevStealer Malware

Fake Claude Desktop App Used to Deploy RevStealer Malware

The malicious software arrives as a 101-megabyte Electron-based archive that mimics Anthropic’s branding to lure users seeking free access to paid AI tools. Upon execution, the application remains invisible, launching an AES-256-CBC-encrypted payload in the background while attempting to add the user's AppData directory to the Microsoft Defender exclusion list to evade detection.

Security researchers highlight that the malware is engineered for stealth, employing rigorous environmental checks to avoid analysis. It requires specific hardware configurations—including at least 2 gigabytes of RAM and two processor cores—and performs timing tests to detect debuggers. Notably, the code automatically terminates if it identifies Russian, Ukrainian, or Central Asian language settings, suggesting a targeted geographical strategy. Once active, it bypasses standard security monitoring by using indirect system-call wrappers to interact directly with the Windows kernel.

Rather than establishing long-term persistence, RevStealer operates as a hit-and-run operation. It performs a rapid sweep for browser cookies, VPN configurations, and crypto-assets before transmitting the stolen data to a command-and-control server and self-deleting. To maintain operational longevity, the malware can fetch alternative server addresses from a smart contract on the Polygon blockchain, allowing operators to rotate their infrastructure without redistributing the malicious files. This campaign follows a broader trend of attackers leveraging high-interest software, such as AI tools and movie downloads, to compromise digital assets.

Share:

Comments (0)

Leave a comment

No comments yet. Be the first!